Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
herrjemand.medium.com
Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
1–10 of 294 posts
Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
#2Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
#3Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
#4The idea to replace CAPTCHA with FIDO doesn't seem sound, isn't it trivial to imitate it with DevTools in Chrome or some other software? https://developer.chrome.com/docs/devtools/webauthn/
(although practically I'm unsure as to whether that's really a good idea or would work well)
Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
#5The idea to replace CAPTCHA with FIDO doesn't seem sound, isn't it trivial to imitate it with DevTools in Chrome or some other software? https://developer.chrome.com/docs/devtools/webauthn/
Meaning you need to buy more. Makes it expensive at least.
Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
#6The idea to replace CAPTCHA with FIDO doesn't seem sound, isn't it trivial to imitate it with DevTools in Chrome or some other software? https://developer.chrome.com/docs/devtools/webauthn/
I believe the idea here is you need to buy actual FIDO U2F keys and they could then be revoked on a per-key basis if you're caught abusing them as they're signed by a 3rd party so can't just be emulated. Meaning you need to buy more. Makes it expensive at least.
Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
#7In theory, couldn’t Yubikey begin reducing batch sizes to 1,000 and Cloudflare mark specific batch numbers as requiring one extra step to verify? The vast majority of Yubikey sales will be for real people in any case.
Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
#8The idea to replace CAPTCHA with FIDO doesn't seem sound, isn't it trivial to imitate it with DevTools in Chrome or some other software? https://developer.chrome.com/docs/devtools/webauthn/
I believe the idea here is you need to buy actual FIDO U2F keys and they could then be revoked on a per-key basis if you're caught abusing them as they're signed by a 3rd party so can't just be emulated. Meaning you need to buy more. Makes it expensive at least.
Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
#9Re: Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
#10This provides effective rate limiting and you can still get every key you automate banned very easily.